Terms of Business
What we agree to do, what we ask of you, and how either of us can end it.
Last updated 23 July 2026
Bleep Digital, poslovno svetovanje, Tomi Toth s.p. ("we", "us") Dekani 151, 6271 Dekani, Slovenia Registered with AJPES, registration number 9000305000 Tax number 44043597 — not liable for VAT (ni zavezanec za DDV)
Version 1.0, effective 23 July 2026.
1. Scope#
1.1 These terms govern all services we provide: website design and development, hosting, domain registration and management, email services, maintenance and support.
1.2 They apply to businesses, sole traders acting in a professional capacity, and public bodies. We do not contract with consumers.
1.3 A client's own terms do not apply, even if we do not expressly object.
2. Formation#
2.1 Our published prices are an invitation to treat, not a binding offer.
2.2 A contract forms when the client accepts a written offer from us — in the client portal, by email, or by signature — and we confirm acceptance.
2.3 Work begins only after the setup fee and first monthly payment are received. We are not obliged to start before payment clears.
3. What we provide#
3.1 The package selected, as described on our website at the time of the offer, including the specified number of pages, storage, mailboxes and support level.
3.2 Hosting on infrastructure we operate or lease, including TLS certificates, security updates, monitoring and backups per the Backup Policy.
3.3 Domain registration and management where included, subject to the registry's own terms. Domains are registered in the client's name; the client is the legal owner.
3.4 Content changes as included in the package. Unused allowances do not carry over.
3.5 Work outside the package is quoted separately and requires written approval before we begin.
4. Client obligations#
4.1 Provide content, images, logos and business information promptly and in usable form.
4.2 Warrant that all supplied material is lawful and that the client holds the necessary rights. The client indemnifies us against third-party claims arising from supplied material.
4.3 Check and approve the site before go-live. Where content is generated with AI assistance, the client is responsible for verifying that business facts — opening hours, prices, contact details, professional qualifications and licensing claims — are correct. Our sign-off step exists for this purpose.
4.4 Keep credentials secure and notify us immediately of suspected compromise.
4.5 Comply with the Acceptable Use Policy.
4.6 Nominate a single contact authorised to approve work and incur charges.
5. Term, renewal and termination#
5.1 Minimum term: 12 months from go-live, unless agreed otherwise in writing.
5.2 After the minimum term the contract continues monthly and may be terminated by either party with 30 days' written notice to the end of a calendar month.
5.3 Either party may terminate immediately for material breach not remedied within 14 days of written notice.
5.4 We may suspend or terminate immediately for breach of the Acceptable Use Policy, or where continued service exposes us or other clients to legal risk or material technical harm.
5.5 Notice may be given by the client in the client portal, without needing to contact us by any other means.
5.6 On termination — what the client receives:
(a) Their domain, transferred on request. Domains are registered in the client's name and we never withhold one, including during a payment dispute. (b) A static export of the website — all pages rendered as HTML together with images and assets, as a single archive, ready to host elsewhere. (c) Their mailboxes as downloadable files in a standard format. (d) Personal data they are entitled to under GDPR, in a structured, machine-readable format, free of charge in every case (see 5.8).
5.7 Export fee. The export at 5.6(b) and (c) is produced by hand and is:
- free where the client has completed 12 months or more of service;
- €499 where the client leaves before completing 12 months.
5.8 The export fee never applies to personal data. Where the client, or a person whose personal data we hold, exercises a right of access or portability under GDPR, we provide that data free of charge and without delay. The fee at 5.7 is for the optional service of producing a ready-to-host copy of the website, not for access to data.
5.9 Deletion. The export is available for 30 days after termination. We then retain data for a further 60 days in case of dispute, and delete it permanently thereafter. Backups age out on their normal cycle and are not retrievable once expired. Clients should download their export before the 30 days expire; after deletion we cannot recover anything.
6. Fees and payment#
6.1 Setup fees are payable in advance. Monthly fees are payable in advance for each period.
6.2 Payment by card, SEPA Direct Debit or bank transfer. Invoices are due within 14 days.
6.3 We are not liable for VAT (ni zavezanec za DDV) under the Slovenian Value Added Tax Act. No VAT is added to our prices and our invoices do not show VAT. The prices quoted are the final amounts payable.
6.3.1 Should we become liable to register for VAT, we will give notice under §6.4 before any VAT-inclusive price takes effect.
6.4 We may change prices with 60 days' written notice. The client may terminate with effect from the change date if they do not accept it.
6.5 Statutory interest applies to late payment. We may suspend services for accounts materially overdue, having given notice.
6.6 Setup fees are non-refundable once work has begun, reflecting work already performed.
7. Intellectual property#
7.1 On full payment, the client owns the content, images and text they supplied, and receives a perpetual, non-exclusive licence to use the website we produced for their business.
7.2 We retain ownership of our underlying platform, templates, component library, tooling and know-how. These are reused across clients and are not transferred.
7.3 Third-party components remain subject to their own licences.
7.4 We may reference the client's name and show the website in our portfolio unless they object in writing.
8. Liability#
This clause most needs legal review. German AGB law voids limitations that go too far, leaving unlimited liability.
8.1 We are fully liable for death or personal injury caused by negligence, for intent and gross negligence, and wherever liability cannot lawfully be excluded.
8.2 For ordinary negligence we are liable only for breach of a material obligation — one essential to the contract and which the client may reasonably rely on — and then only for foreseeable, contract-typical damage.
8.3 Otherwise our total liability is limited to the fees paid in the 12 months preceding the event.
8.4 We are not liable for: (a) loss of profit, revenue, goodwill, or anticipated savings; (b) content supplied or approved by the client, including AI-assisted content the client signed off; (c) failures of third parties outside our control — upstream providers, registries, certificate authorities, payment processors, email recipients; (d) DNS or domain changes made by the client or their registrar; (e) unauthorised access resulting from the client's own credentials; (f) force majeure, including outages, attacks, and interruptions to power or connectivity beyond our reasonable control; (g) loss of data where the client's own copy would have prevented it — see the Backup Policy; (h) search engine rankings, traffic, or commercial outcomes.
8.5 The Service Level Agreement sets out the exclusive remedy for downtime.
9. Infrastructure and force majeure#
9.1 Where the service runs#
9.1.1 Services are hosted on infrastructure leased from OVH SAS, in datacentres located within the European Union. Client data does not leave the EU in the ordinary course of the service.
9.1.2 We may change infrastructure provider or datacentre location, remaining within the EU or an adequate jurisdiction, on 30 days' notice.
9.1.3 We depend on third parties we do not control: the infrastructure provider, domain registries, certificate authorities, payment processors, DNS providers and recipient mail servers. Their failures are outside our control and are addressed at 9.2.
9.2 Force majeure#
9.2.1 Neither party is liable for failure to perform caused by events beyond its reasonable control. For the avoidance of doubt these include:
(a) fire, flood, explosion or physical destruction of a datacentre. This is a real, not theoretical, risk: in March 2021 a fire destroyed an OVH datacentre in Strasbourg and customers without independent backups permanently lost data; (b) failure of the infrastructure provider, including insolvency, prolonged outage, or termination of their service to us; (c) natural disaster, earthquake, severe weather, pandemic or epidemic; (d) war, terrorism, civil unrest, sabotage; (e) failure of public power, telecommunications or internet infrastructure; (f) large-scale cyber-attack, including distributed denial of service, whether directed at us or at our providers; (g) act of government, embargo, sanction, or change of law preventing performance; (h) strike or industrial action other than by our own staff; (i) failure or compromise of a third-party service the client's site depends on, including registries, certificate authorities and payment processors.
9.2.2 The affected party notifies the other as soon as practicable and uses reasonable efforts to resume.
9.2.3 Service credits under the SLA do not accrue during force majeure.
9.2.4 If force majeure continues for more than 30 consecutive days, either party may terminate on written notice without liability. We refund fees paid for service not delivered.
9.2.5 Limits of our backup obligation. We take backups as described in the Backup Policy and we hold them separately from the systems they protect. Nonetheless, an event that destroys both the primary infrastructure and the backup copies is possible. We do not warrant that data can be recovered in every circumstance. Clients whose business could not survive the loss of their website or mail should keep their own independent copy, and we will help them set that up on request.
10. Security incidents, attacks and data breaches#
10.1 We take security seriously and we do not pretend it is absolute. No hosting provider can guarantee that a system will never be compromised. What we commit to is competence before an incident and honesty during one.
10.2 What we do to prevent incidents#
Security updates applied to the platform, operating system and runtimes; per-client isolation so a compromise of one site does not reach another; encrypted connections throughout; encrypted backups held in a separate datacentre; automated blocking of repeated authentication attempts; and a firewall permitting only the ports the service requires. Detail is in the Data Processing Agreement §9.
10.3 What we do when an incident happens#
10.3.1 We tell you. Where a security incident affects your site, your data or your mailboxes, we notify you without undue delay, and in any case within 72 hours of becoming aware where personal data is affected.
10.3.2 We tell you what happened, what data was affected, what we have done, and what you should do. We do not conceal incidents or delay disclosure to manage reputation.
10.3.3 We contain the incident, restore service, and where restoration from backup is required we do so at no charge — an incident on our side is not a chargeable restore.
10.3.4 Where the law requires notification to a supervisory authority or to affected individuals, we assist you as processor. The obligation to notify is yours as controller; ours is to give you what you need to meet it.
10.4 Where responsibility sits#
10.4.1 We are responsible for the security of the platform, the servers, and the software we supply and maintain.
10.4.2 You are responsible for: (a) keeping your credentials confidential, using strong and unique passwords, and enabling two-factor authentication where offered; (b) who you grant access to, and revoking it when they leave; (c) any software, plugin, script or integration you or a third party add that we did not supply; (d) the content you publish and the personal data you choose to collect.
10.4.3 We are not liable for a compromise arising from your own credentials being disclosed, guessed or reused, nor from software you introduced. We will still help you recover — that help is not an admission of liability.
10.4.4 Where an incident results from our failure to apply a security update we should reasonably have applied, or from a defect in what we built, liability follows §8.
10.5 Vulnerabilities and disclosure#
10.5.1 Report suspected vulnerabilities to security@bleep-digital.com. We investigate promptly and will not pursue anyone who reports a genuine issue in good faith and without exploiting it.
10.5.2 We may apply an emergency security update without the notice period in the SLA where delay would expose clients to risk. We tell you as soon as practicable afterwards.
10.5.3 Where a vulnerability requires it, we may temporarily suspend a specific function or an entire site to protect that client and others. Suspension is the shortest we can make it and we explain why.
10.6 Ransomware and destructive attacks#
10.6.1 We will not pay a ransom. Our response is to restore from backup. This is why the Backup Policy and its retention periods matter, and why we test restores quarterly.
10.6.2 Backups are held in a separate datacentre precisely so that an attack on the primary systems does not reach them.
10.6.3 We cannot guarantee recovery in every circumstance — see §9.2.5 and the Backup Policy §7. A client whose business could not survive the loss of its website or mail should keep an independent copy, and we will help set that up at no charge.
11. Data protection#
11.1 Both parties comply with GDPR and applicable national law.
11.2 Where we process personal data on the client's behalf, the Data Processing Agreement applies and forms part of this contract.
11.3 The client is the controller for personal data on their website and in their mailboxes and is responsible for its lawful basis.
12. Confidentiality#
Each party keeps the other's confidential information confidential and uses it only to perform the contract. Survives termination by three years.
13. Changes to these terms#
We may amend these terms with 60 days' notice. If the client objects in writing before the change takes effect, they may terminate as at that date.
14. General#
14.1 Governing law: the Republic of Slovenia. 14.2 Jurisdiction: courts of Koper. 14.3 If a provision is invalid, the rest stands. 14.4 Amendments must be in writing. 14.5 The client may not assign without our consent; we may assign to a successor on notice.